> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 670 Events, 549 Actors

> Two figures that turn a severity breakdown into a specific, bounded response task

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/XtQuNxdDTqAwCnod/images/case19.png?fit=max&auto=format&n=XtQuNxdDTqAwCnod&q=85&s=a982876f05dfcab95477bfe4f925bf7e" width="1478" height="366" data-path="images/case19.png" />

Combining High and Critical severity from the same analysis window gives **670** events, 3.04% of permitted traffic, averaging 27.9 per hour, up **30%** against the prior comparison period. Behind those events sit **549** unique threat actors — distinct source IPs.

***

## Why these two numbers are grouped together

670 is an event count; 549 is a source count. Read together, they say something an event count alone doesn't: the high-severity traffic in this window isn't dominated by a small number of actors making repeated attempts, it's spread across a comparably large set of distinct sources — roughly 1.2 events per actor. That ratio matters for response planning, since it rules out the possibility of resolving most of the exposure by addressing one or two persistent IPs.

## The 30% is a change indicator, not a static count

This figure is measured against the prior period, not presented as an absolute. An increase of this size in high-severity permitted traffic is the kind of shift a continuously running analysis surfaces immediately, rather than something that would only become visible on the next scheduled reporting cycle.

## What "permitted, then intercepted" means

Both figures describe traffic the client's firewall already allowed through. OneFirewall's detection layer classified and intercepted it after the fact, which is why these numbers exist as a distinct category rather than being folded into the firewall's own blocked-traffic count.

***

Proof of Value engagements surface this same event-to-actor ratio against a client's own high-severity traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
